All articles Bot detection

Detecting Fake Reviews: Stopping Review Farms on Marketplaces

A product jumps from twelve reviews to three hundred over a weekend, all glowing, all vaguely worded. The reviews look like they came from hundreds of shoppers, but they came from a handful of machines running a script.

Fake reviews corrode the one thing a marketplace sells: trust in what other buyers say. Text analysis alone loses this race, because farms now generate fluent, varied prose. The durable signal is the environment the reviews were written from.

How review farms actually operate

Volume is the whole business model, and volume leaves fingerprints:

  • Account-per-review economics. A farm controls many identities but owns few devices. Renting a thousand phones is expensive; running a thousand accounts from ten emulators is cheap.
  • Automation. Reviews get posted through scripted browsers and mobile automation, not human sessions, so timing and interaction patterns cluster unnaturally.
  • Concealment tooling. To dodge naive checks, farms rotate proxies and use antidetect browsers that spoof user agents, canvas, and fonts.

Each of those shortcuts is a chance to catch them. The farm’s strength — doing the same thing at scale — is also its weakness.

The device signals that expose them

A cloud platform like Prynt gives every reviewer session a stable visitorId derived from hundreds of hardware and browser attributes. When two hundred “different” reviewers resolve to nine visitorIds, the farm is visible no matter how varied the review text is.

Server-side Smart Signals sharpen the picture:

  • Emulator and VM detection flags reviews written from farmed Android images rather than real phones.
  • Antidetect-browser and tampering flags catch the exact tools sold to make each fake account look unique.
  • Datacenter and residential-proxy reputation exposes the IP infrastructure behind coordinated posting.
  • Automation indicators separate scripted submissions from genuine human sessions.

Because the analysis happens server-side, a farm cannot see which checks fired or tune against them from the client. That asymmetry matters: a client-side-only defense hands the attacker a debugging console, while server-side signals keep your logic private and force the farm to guess.

Building a review-integrity pipeline

Device intelligence works best as one stage in a scored pipeline, not a single gate:

  1. Capture at submission. Attach the visitorId and Smart Signals to every review the moment it is posted, before it becomes public.
  2. Correlate across the review graph. Count how many accounts, how many reviews for one seller, and how many purchases trace to each device. A single device behind many “verified” purchases of one product is classic brushing.
  3. Score, then route. Auto-publish low-risk reviews instantly, hold medium-risk for moderation, and reject or shadow-hold the clearest farm clusters.
  4. Feed enforcement. When a cluster is confirmed, the shared visitorIds also help you find the seller who bought the reviews.

For the coordinated bot behavior underneath most farms, our bot detection overview explains how automation and headless environments are flagged before they ever reach moderation.

Keeping honest reviewers unblocked

Aggressive filtering that eats real reviews is its own failure. A few principles keep the system fair:

  • Score, do not slam. Let the confidence score drive graduated responses so a genuine shopper on a shared office network is not auto-rejected.
  • Weigh corroboration. A device match plus a verified purchase plus normal session timing looks very different from a match with none of those.
  • Stay explainable. Retain the signals behind each hold so moderators can clear false positives quickly and confidently.

It also pays to watch the shape of the campaign over time. Genuine reviews for a product arrive as a diffuse trickle spread across many real devices and locations; a farm arrives as a burst concentrated on a few environments, often right after a seller pays for a boost. Tracking review velocity per seller alongside device concentration turns a subtle anomaly into an obvious spike your moderators can investigate before buyers are misled.

The goal is not to interrogate every happy customer. It is to make the farm’s economics collapse: if two hundred accounts collapse into nine devices, one takedown removes the whole campaign.

Fake reviews will keep evolving their wording, but they cannot cheaply evolve their way out of running from a small pool of real machines. Anchor integrity to the device and the farm’s scale becomes the thing that gives it away.

Try submitting from a fresh incognito window and watch the visitorId hold steady in the live playground, or review plans on the pricing page to start scoring reviews today.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading